๐Ÿ” CVE Alert

CVE-2026-27980

UNKNOWN 0.0

Next.js: Unbounded next/image disk cache growth can exhaust storage

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Next.js is a React framework for building full-stack web applications. Starting in version 10.0.0 and prior to version 16.1.7, the default Next.js image optimization disk cache (`/_next/image`) did not have a configurable upper bound, allowing unbounded cache growth. An attacker could generate many unique image-optimization variants and exhaust disk space, causing denial of service. This is fixed in version 16.1.7 by adding an LRU-backed disk cache with `images.maximumDiskCacheSize`, including eviction of least-recently-used entries when the limit is exceeded. Setting `maximumDiskCacheSize: 0` disables disk caching. If upgrading is not immediately possible, periodically clean `.next/cache/images` and/or reduce variant cardinality (e.g., tighten values for `images.localPatterns`, `images.remotePatterns`, and `images.qualities`).

CWE CWE-400
Vendor vercel
Product next.js
Published Mar 18, 2026
Last Updated Mar 18, 2026
Stay Ahead of the Next One

Get instant alerts for vercel next.js

Be the first to know when new unknown vulnerabilities affecting vercel next.js are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

vercel / next.js
>= 10.0.0, < 16.1.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/vercel/next.js/security/advisories/GHSA-3x4c-7xq6-9pq8 github.com: https://github.com/vercel/next.js/commit/39eb8e0ac498b48855a0430fbf4c22276a73b4bd github.com: https://github.com/vercel/next.js/releases/tag/v16.1.7